Digital signing wouldn't defend you from a compromised build server.
What in that act says OpenWrt would be made illegal? If anything, OpenWrt would roll out automated security updates for a supported branched release to comply with these regulations.
Also, if you actually read it, there are exceptions for open source software!
Reproducible Builds and multiple distributed builders would though.
https://reproducible-builds.org/